Lucky Savings.dll

Lucky Savings

Innovative Apps

This web browser extension uses the Crossrider toolbar creation and distribution platform. The module Lucky Savings.dll, “Lucky Savings BHO” by Innovative Apps has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘CrossriderApp0012759’.
Publisher:
Innovative Apps  (signed and verified)

Product:
Lucky Savings

Description:
Lucky Savings BHO

Version:
1.1.153.91

MD5:
b155b8cc63d5b2813e36c4e4084b6bf2

SHA-1:
410dc0f77a666ea70cf2dc33446b44520af2b947

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/20/2024 12:05:35 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.50OnRed.InnovativeApps (M)
16.2.8.10

File size:
730.9 KB (748,424 bytes)

Product version:
1.1.153.91

Copyright:
Copyright 2011

Original file name:
Lucky Savings.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\lucky savings\lucky savings.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
1/8/2013 7:00:00 PM

Valid to:
1/9/2014 6:59:59 PM

Subject:
CN=Innovative Apps, O=Innovative Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5419E32FDAD7A6E5666A35066C5EAAC5

Registration
CLSIDs:
{11111111-1111-1111-1111-110111271159}, {22222222-2222-2222-2222-220122272259}

ProgIDs:
CrossriderApp0012759.BHO.1, CrossriderApp0012759.Sandbox.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
4/3/2013 4:20:20 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:MwXghe209lcVzpbIQ0tvZ5BRWRbi3ok8NKT+lSPoIIlYwsARHW:xXgg20Hc9pbIQ0voQ3okNT+lSNPpABW

Entry address:
0x4B82D

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, BC, B1, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 85, C0, 74, 12, 83, E8, 08, 81, 38, DD, DD, 00, 00, 75, 07, 50, E8, A2, B7, FF, FF, 59, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 10, A1, C0, 6F, 0A, 10, 33, C5, 89, 45, FC, 8B, 55, 18, 53, 33, DB, 56, 57, 3B, D3, 7E, 1F, 8B, 45, 14, 8B, CA, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, C2, 2B, C1, 48, 3B, C2, 7D, 01, 40, 89, 45, 18...
 
[+]

Entropy:
6.6202

Code size:
518.5 KB (530,944 bytes)

Internet Explorer BHO
Display name:
CrossriderApp0012759

CLSID:
{11111111-1111-1111-1111-110111271159}

CLSID name:
Lucky Savings


Remove Lucky Savings.dll - Powered by Reason Core Security